Strange bandwidth originating from RB

Hi all,

I’m having a problem where my upload bandwidth is near constantly maxed causing terrible latency on my link, however I’m not able to find any devices on my network generating these uploads.

The RB interface statistics are also skewed, the WAN interface shows 20gb uploaded whereas the LAN interface only shows 3.7gb of data. I don’t have any other interfaces enabled which makes me think this traffic must be generated on the RB?

I’ve got only 1 user account with the password changed twice recently, telnet disabled, web & ssh ports changed from default, no strange activity in the system log, how can i track this down?

Cheers!

IMHO you are victiom of DNS DDOS attack.
Look here: http://forum.mikrotik.com/t/blocking-dns-amplification-ddos-is-using-your-routerboard/83335/1